Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-74 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 526 | 524 | 2 |
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▄█▆▆
2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 2 · 2026-03 1 · 2026-04 0 · 2026-05 82 · 2026-06 171 · 2026-07 134 · 2026-08 134
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2019-2725 | 9.8 | 100.0 | KEV | Oracle WebLogic Server |
| CVE-2022-27924 | 7.5 | 99.7 | KEV | Synacor Zimbra Collaboration Suite (ZCS) |
| CVE-2026-10060 | 2.1 | 91.6 | — | TRENDnet TEW-432BRP formSetRoute command injection |
| CVE-2026-10061 | 2.1 | 91.6 | — | TRENDnet TEW-432BRP formWPS command injection |
| CVE-2026-10878 | 2.1 | 90.2 | — | D-Link DWR-M920 formSmsManage sub_41C8E8 command injection |
| CVE-2026-11339 | 2.1 | 86.8 | — | D-Link DWR-M920 formUSSDSetup sub_41CF20 command injection |
| CVE-2026-18814 | 7.3 | 84.8 | — | H3C NX15 esps reload.reload_config command injection |
| CVE-2026-18686 | 8.9 | 84.2 | — | GL.iNet GL-MT3000 nas-web RPC Wrapper glc nas-web.add_user command injection |
| CVE-2026-19348 | 8.9 | 83.2 | — | Shenzhen Aitemi M300 Wi-Fi Repeater protocol.csp sprintf command injection |
| CVE-2026-12197 | 7.3 | 82.6 | — | Ruijie EG105G-P JSON-RPC Diagnose Endpoint diagnose nslookup command injection |
| CVE-2026-18902 | 7.3 | 82.6 | — | H3C NX15 esps repeaterproc command injection |
| CVE-2026-18601 | 8.9 | 82.5 | — | GL.iNet GL-MT3000 ovpn-client.so Native Plugin glc ovpn-client.check_config command inj… |
| CVE-2026-19747 | 8.9 | 82.4 | — | Tenda CH7 ATE Module Kylin HandleCmd command injection |
| CVE-2026-18811 | 7.3 | 81.6 | — | H3C NX15 esps add command injection |
| CVE-2026-18812 | 7.3 | 81.6 | — | H3C NX15 esps esps.ipv6.wan command injection |
| CVE-2026-18813 | 7.3 | 81.6 | — | H3C NX15 esps delete command injection |
| CVE-2026-19346 | 7.4 | 81.2 | — | Tenda CH22 CertListInfo formCertListInfo command injection |
| CVE-2026-6279 | 9.8 | 80.8 | — | Avada (Fusion) Builder <= 3.15.2 - Unauthenticated Remote Code Execution via PHP Functi… |
| CVE-2026-18612 | 8.9 | 80.7 | — | GL-iNet GL-MT3000 plugins.so Native Plugin glc plugins.install_package command injection |
| CVE-2026-9423 | 2.0 | 80.0 | — | Edimax BR-6675nD POST Request mp command injection |
| Vendor | CVEs |
|---|---|
| itsourcecode | 79 |
| sourcecodester | 72 |
| code-projects | 56 |
| codeastro | 36 |
| edimax | 23 |
| gl.inet | 19 |
| microsoft | 7 |
| nousresearch | 7 |
| trendnet | 7 |
| h3c | 6 |
| gl-inet | 5 |
| acacode | 4 |
| apache | 4 |
| cisco | 4 |
| jinher | 4 |